Re: Gmane's certificate

Joseph Mingrone <[email protected]>
Newsgroups gmane.discuss
Message-ID <[email protected]>
Joseph Mingrone <[email protected]> writes:

> Hi,

> When trying to connect to news.gname.org [1], GnuTLS complains about the
> certificate [2].  A workaround is to download the certificate and update
> `gnutls-trustfiles' to point to it.  But, now that Let's Encrypt offers
> free certificates, could Gmane use a certificate issued by a recognized
> authority?

> Thanks,

> Joseph

> [1]
> (setq (gnus-secondary-select-methods
>    '((nntp "news.gmane.org"
>            (nntp-port-number 563)
>            (nntp-open-connection-function nntp-open-tls-stream))))

> [2]
> Checking new news...
> gnutls.c: [1] (Emacs) connecting to host: news.gmane.org
> gnutls.c: [1] (Emacs) allocating credentials
> gnutls.c: [2] (Emacs) allocating x509 credentials
> gnutls.c: [2] (Emacs) using default verification flags
> gnutls.c: [1] (Emacs) setting the trustfile:  /usr/local/share/certs/ca-root-nss.crt
> gnutls.c: [1] (Emacs) gnutls callbacks
> gnutls.c: [1] (Emacs) gnutls_init
> gnutls.c: [1] (Emacs) got non-default priority string: NORMAL
> gnutls.c: [1] (Emacs) setting the priority string
> gnutls.c: [2] HSK[0x3202000]: sent server name: 'news.gmane.org'

> gnutls.c: [1] (Emacs) non-fatal error: Resource temporarily unavailable, try again. [5358 times]
> gnutls.c: [2] GNUTLS_SEC_PARAM_LOW: certificate's issuer security level is unacceptable

> gnutls.c: [1] (Emacs) verification: certificate was signed with an insecure algorithm
> gnutls.c: [1] (Emacs) verification: the certificate was signed by an unknown and therefore untrusted authority
> gnutls.c: [1] (Emacs) verification: certificate could not be verified

And now the certificate has expired.

% gnutls-cli --crlf news.gmane.org -p nntps <<<QUIT
Processed 154 CA certificate(s).
Resolving 'news.gmane.org:nntps'...
Connecting to '195.159.176.226:563'...
- Certificate type: X.509
- Got a certificate list of 1 certificates.
- Certificate[0] info:
 - subject `CN=news.gmane.org,O=Gmane,ST=Some-State,C=NO', issuer `CN=news.gmane.org,O=Gmane,ST=Some-State,C=NO', serial 0x009398630d3ab6ffd6, RSA key 1024 bits, signed using RSA-SHA1, activated `2015-01-13 21:13:46 UTC', expires `2018-01-12 21:13:46 UTC', pin-sha256="V/d+/hePkSL5MylBGzvZ/c21qMz+E9H1SfyP1NKBr1Y="
        Public Key ID:
                sha1:d21a01452b5a9b06106946930e64717869ff7ae0
                sha256:57f77efe178f9122f93329411b3bd9fdcdb5a8ccfe13d1f549fc8fd4d281af56
        Public Key PIN:
                pin-sha256:V/d+/hePkSL5MylBGzvZ/c21qMz+E9H1SfyP1NKBr1Y=
        Public key's random art:
                +--[ RSA 1024]----+
                |=O+.ooo          |
                |+*o+ . .         |
                |= + + o          |
                | . + = o         |
                |  . + + S        |
                |   . . =         |
                |    . +          |
                |     E .         |
                |      .          |
                +-----------------+

- Status: The certificate is NOT trusted. The certificate issuer is unknown. The certificate chain uses insecure algorithm. The certificate chain uses expired certificate.
*** PKI verification of server certificate failed...
*** Fatal error: Error in the certificate.
*** handshake has failed: Error in the certificate.

_______________________________________________
Gmane-discuss mailing list
[email protected]
http://hawk.netfonds.no/cgi-bin/mailman/listinfo/gmane-discuss
signature.asc (application/pgp-signature, 962 B)
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEVbCTpybDiFVxIrrVNqQMg7DW754FAlpcOr5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDU1
QjA5M0E3MjZDMzg4NTU3MTIyQkFENTM2QTQwQzgzQjBENkVGOUUACgkQNqQMg7DW
7572Ow/9HrcDB74rkLdQG7XzbVO26WeCyo1QxbTY1S8uchEysNxB2CskwRfVHcDu
E21+82yj3w7GpQc+d0t5d8rlq3ps73DwNcRrThEDfUJ3BiKgT0rAg5hAHpAAzyq/
7ws5B6IQxRP7ZFVEGJzIz7RuklDqOZSs/XporYISmjJTzKDyV3U79mF8UO0zkyG1
NQ0/Q8CHs0Qv8G7KZ2K1ha9cynOMCcjyUZtWyECE2E4+IKknkyCqDUDJEccD1SHG
iJxO+rS3wRu04/XBhlFxbSB1xIU1euKCt4ze/mbN0j0jgbDd02ER7kGMW/nLp8u4
flirsinqSOkDC84xyNk73syTaIAv+2VUbrHGKNy1LJcu0r2wp2YO7WKT9Ct825m5
Wt0NwrW2pCBdkGsv3tjM75PH0tYIYBqBY7wxyqzzjNYbWW0Nvkk3MdrTBWhjzjmT
wWgYcTOQzpaU/et32ERAAUJ2/sYWIbHIiYdHp7z9cz0BLna6fqT8xUc2THwPJx6I
6ov6THGgVpHOjuvno9BoZLDwkppE1fpL2k2AXszPX/0TVml3bWWpH0E/IzXqQ1pw
6DCWGraJBsDjyUDeyXxG9//yKNxxsCb1xJ5EwUt2ZZR373PQLMfEIE53A0jrOnxQ
dWUu0DwrhInp18F3+I4uy3xcDhr4nIJ6WvyAc7RKRcSsm1lOTU0=
=kqC1
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.